Use-after-free vulnerability in bzip2recover in bzip2 1.0.6 allows remote attackers to cause a denial of service (crash) via a crafted bzip2 file, related to block ends set to before the start of the block.
CVSS Details
- CVSS 3.1 Base Score: 6.5
- CVSS 3.1 Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Alpine Linux | — | Upgrade bzip2 | Aug 22, 2024 | Jun 30, 2016 |
| Arch Linux | — | Upgrade to the latest version of Arch Linux | Jul 11, 2025 | Jun 30, 2016 |
| Debian | — | Upgrade bzip2 | Jun 25, 2019 | Jun 30, 2016 |
| Freebsd | — | Upgrade bzip2Upgrade FreeBSD | Oct 24, 2019 | Oct 24, 2019 |
| Gentoo Linux | — | Upgrade app-arch/bzip2. | Oct 30, 2017 | Jun 30, 2016 |
| Huawei Euleros 2_0_sp2 | — | Upgrade bzip2-develUpgrade bzip2-libsUpgrade bzip2 | Dec 4, 2019 | Jun 30, 2016 |
| Huawei Euleros 2_0_sp3 | — | Upgrade bzip2-develUpgrade bzip2-libsUpgrade bzip2 | Dec 18, 2019 | Jun 30, 2016 |
| Huawei Euleros 2_0_sp5 | — | Upgrade bzip2Upgrade bzip2-libsUpgrade bzip2-devel | Feb 15, 2019 | Jun 30, 2016 |
| Oracle Solaris | — | Upgrade compress/bzip2 to version 1.0.6-0.175.3.10.0.4.0 on Solaris 11.3 | May 29, 2017 | Jun 30, 2016 |
| Redhat_linux | — | No solution exists | Jul 9, 2025 | Jun 20, 2016 |
| Suse | — | Upgrade bzip2Upgrade bzip2-docUpgrade libbz2-develUpgrade libbz2-1-32bitUpgrade libbz2-1Upgrade libbz2-devel-32bit | May 16, 2019 | Jun 30, 2016 |
| Ubuntu | — | Upgrade bzip2Upgrade libbz2-1.0 (Ubuntu Pro)Upgrade lib32bz2-1.0 (Ubuntu Pro)Upgrade bzip2 (Ubuntu Pro)Upgrade libbz2-1.0Upgrade lib64bz2-1.0Upgrade lib64bz2-1.0 (Ubuntu Pro)Upgrade lib32bz2-1.0 | Jun 26, 2019 | Jun 30, 2016 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub